## IP Intelligence Briefing: 137.255.13.37
Classification: Low Risk / Single-Service Host
Report Date: 2026-07-29
Analyst: IPDebrief Intelligence Unit
---
Executive Summary
IP 137.255.13.37 presents as a low-risk (Score: 25) single-service host operating in London, GB under ASN 328228. The IP hosts SSH services and is associated with the Benin TLD domain sbin.bj. While currently low-risk, neighborhood context and historical data warrant monitoring for potential abuse escalation.
---
Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **ASN** | 328228 |
| **Organization** | Vivien ASSANGBE |
| **CIDR Block** | 137.255.12.0/22 |
| **Geolocation** | London, GB |
| **DNS PTR** | sbin.bj |
| **Open Ports** | 22/tcp (SSH) |
| **Service Type** | Single-Service Host |
---
Threat Indicators
Current Status:
- No active threat indicators detected
- No known attacker or spam source classification
- Zero blacklist entries at time of assessment
- No Tor exit node or proxy designation
Historical Anomalies:
- DNSBL listing observed (1 of 8 total lists, severity: high)
- Geolocation discrepancy noted: historical observations indicate Benin (BJ), current profile shows London, GB
- 17 total signal observations recorded
---
Neighborhood Context (137.255.13.0/24)
Subnet Abuse Density: 0.3333 (Mixed classification)
Sibling Analysis: 9 total IPs, 6 active, 3 threat siblings
High-Risk Neighbors to Monitor:
- 137.255.13.19: Risk Score 65 (Authority: 50)
- 137.255.13.44, 137.255.13.53, 137.255.13.247: Risk Score 50 (Authority: 50)
Low-Risk Neighbors:
- 137.255.13.90, 137.255.13.211: Risk Score 25
- 137.255.13.181, 137.255.13.201: Risk Score 0
---
Recommended Actions
Firewall Rules:
- Allow inbound SSH (port 22) from trusted networks only
- Block all other inbound traffic to 137.255.13.37/32
Monitoring Priorities:
- Monitor for SSH brute-force attempts (port 22)
- Watch for geolocation shifts to Benin or other African regions
- Track DNSBL listing status changes
Correlation:
- Investigate relationship with sbin.bj domain for potential abuse indicators
- Review all 137.255.13.0/24 siblings for coordinated malicious activity
---
Risk Assessment
The IP maintains a low-risk profile with single-service characteristics. However, the mixed-risk neighborhood context and historical DNSBL activity suggest potential for abuse escalation. No immediate blocking is warranted, but continued monitoring is recommended, particularly if traffic patterns shift or if additional siblings in the /24 subnet show increased threat activity.
Priority: Monitor
Action: Standard logging and traffic analysis
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Vivien ASSANGBE |
| ASN | AS328228 |
| Network Name | 137.255.12.0 - 137.255.15.255 |
| CIDR Block | 137.255.12.0/22 |
| RIR | ARIN |
| Country | BJ |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | sbin.bj |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | sbin.bj |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:04:56 UTC |
| Last Seen | 2026-08-02 10:53:18 UTC |
| Profile Built | 2026-07-29 19:45:08 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.